DocumentCode
855881
Title
Resilient self-organizing overlay networks for security update delivery
Author
Li, Jun ; Reiher, Peter L. ; Popek, Gerald J.
Author_Institution
Dept. of Comput. & Inf. Sci., Univ. of Oregon, Eugene, OR, USA
Volume
22
Issue
1
fYear
2004
Firstpage
189
Lastpage
202
Abstract
Rapid and widespread dissemination of security updates throughout the Internet will be invaluable for many purposes, including sending early-warning signals, updating certificate revocation lists, distributing new virus signatures, etc. Notifying a large number of machines securely, quickly, and reliably is challenging. Such a system must outpace the propagation of threats, handle complexities in a large-scale environment, deal with interruption attacks on dissemination, and also secure itself. Revere addresses these problems by building a large-scale, self-organizing, and resilient overlay network on top of the Internet. We discuss how to secure the dissemination procedure and the overlay network, considering possible attacks and countermeasures. We present experimental measurements of a prototype implementation of Revere gathered using a large-scale-oriented approach. These measurements suggest that Revere can deliver security updates at the required scale, speed and resiliency for a reasonable cost.
Keywords
Internet; security of data; telecommunication security; Internet; Revere overlay network; certificate revocation list updates; dissemination procedure; early-warning signals; interruption attacks; resilient self-organizing overlay networks; secure network; security update delivery; virus signatures; Broadcasting; Costs; IP networks; Information security; Internet; Large-scale systems; Power system security; Prototypes; Unicast; Velocity measurement;
fLanguage
English
Journal_Title
Selected Areas in Communications, IEEE Journal on
Publisher
ieee
ISSN
0733-8716
Type
jour
DOI
10.1109/JSAC.2003.818808
Filename
1258125
Link To Document